MAL-2026-10755
Dashboard / Malicious Package / MAL-2026-10755
MAL-2026-10755
Summary: Malicious code in captcha-solve-api (PyPI)
Details: Source: amazon-inspector (99621af0900df34246c87811ea5c2a643f2b3805601136dcc0a6768e48af925f) The PyPI package captcha-solve-api contains no captcha functionality and is instead a binary dropper disguised as an analytics SDK. A custom setuptools install class copies telemetry.pth into site-packages, and site.py auto-executes its `import _telemetry_init` line at every Python interpreter start. `_telemetry_init._bootstrap()` spawns a daemon thread that runs `_telemetry_transport.Client.initialize()`, which selects a per-OS/arch asset path (`/pkg/package`, `/pkg/package-arm64`, `/pkg/loader_mac`, `/pkg/package.exe`) from rotating Cloudflare Worker hosts (package-proxy.cf5oobworker.workers.dev, package-proxy.cf8oobworker.workers.dev, package-proxy.cf12oobworker.workers.dev, package-proxy.cf17-ddb.workers.dev, package-proxy.cf25-6eb.workers.dev), downloads the payload, chmods it 0o755 on Unix or invokes CreateProcess via ctypes on Windows, and executes it with the installer's privileges. When HTTP mirrors are unreachable, a DNS-TXT covert channel queries hardcoded subdomains under *.dl.well1.site (tin/tina/ldr/win.dl.well1.site) via public resolvers 8.8.8.8 and 1.1.1.1, reassembles multi-segment TXT records, and base64-decodes them to reconstruct config or payload. The `_telemetry_init` / `_telemetry_transport` module naming, Sentry-style framing, and DISABLE_TELEMETRY opt-out language are cover for the dropper. Installing this package results in remote code execution on every subsequent Python interpreter start on the host. Source: kam193 (6745bff1a72b44a9e53129210993aa7a3d0b95e8d9a0a2b2cdfe91324a8e8477) Package presents little functionality, but excessive fake 'telemetry' module. This fake telemetry is used to download and run malicious executables. Code is designed to survive different blocks: first, there is an attempt to download the executable from one of five Cloudflare Workers. If it's not successful, the code falls back to download using DNS: first, it gets a TXT record from one of c.*.dl.well1[.]site domains, depending on the system. This record returns a number, which is then used to iterate over domains in the form <0...n>.*.dl.well1[.]site and reconstruct the encoded executable from their TXT records. The downloaded binary is then executed and removed afterward. Using a PTH file ensures persistence and runs on every Python start. In this campaign, versions 0.0.1 hold disarmed code (without the necessary configuration), which is completed in further updates. This is a continuation of the 2026-07-haproxy-config-client campaign. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-andreiiiiiii_i Reasons (based on the campaign): - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - The package overrides the install command in setup.py to execute malicious code during installation. - Downloads and executes a remote executable. - covering-tracks - persistence - abuses-pth - data-stored-in-dns
References: https://pypi.org/project/captcha-solve-api/0.0.1/, https://bad-packages.kam193.eu/pypi/package/captcha-solve-api, https://www.virustotal.com/gui/file/06f1c2f0c66cf13ab6702414e8dce7c4115939f3e9cf95e9a8baade58961c016/detection, https://www.virustotal.com/gui/file/230f81f18608800912def92e18999874e004cd9fb4a554f759f77e4dd2030081/detection, https://www.virustotal.com/gui/file/c98444d6aebfd87f2f4412e1d7aafe8fe3fe080139ca1111049ea83fe828cd1d/detection, https://www.virustotal.com/gui/file/1360bb7437f5e7790747bc4e31eedcd19f88f23b20362a42368f4179b8b9e27d/detection, https://tria.ge/260720-teqmlshs6y/behavioral1, https://pypi.org/project/captcha-solve-api/8.5.3/, https://pypi.org/project/captcha-solve-api/8.5.4/
Affected packages
Package
Name: captcha-solve-api
Purl: pkg:pypi/captcha-solve-api
Affected ranges
Type: N/A
Events:
